PT-2024-20529 · Typo3 Cms+1 · Typo3/Cms+1

Derhansen

·

Published

2024-02-13

·

Updated

2024-10-18

·

CVE-2024-24751

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions sf event mgt versions prior to 7.4.0
Description The existing access control check for events in the backend module of sf event mgt, an event management and registration extension for the TYPO3 CMS, got broken during the update to TYPO3 12.4. This occurred because the RedirectResponse from the $this->redirect() function was never handled.
Recommendations For versions prior to 7.4.0, upgrade to version 7.4.0 to address the issue. As a temporary workaround, consider disabling the $this->redirect() function in the affected backend module until the upgrade is applied. Restrict access to the backend module to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24751
GHSA-4576-PGH2-G34J

Affected Products

Typo3/Cms
Sf Event Mgt